Repository navigation
chore: Bump the actions group across 1 directory with 2 updates - #12
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the actions group with 2 updates in the / directory: [googleapis/release-please-action](https://github.com/googleapis/release-please-action) and [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request). Updates `googleapis/release-please-action` from 4 to 5 - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](googleapis/release-please-action@v4...v5) Updates `signpath/github-action-submit-signing-request` from 2 to 3 - [Release notes](https://github.com/signpath/github-action-submit-signing-request/releases) - [Commits](SignPath/github-action-submit-signing-request@v2...v3) --- updated-dependencies: - dependency-name: googleapis/release-please-action dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: signpath/github-action-submit-signing-request dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.
Graphify review — findings
Bumps googleapis/release-please-action from v4 to v5 for cutting releases, and signpath/github-action-submit-signing-request from v2 to v3 for signing the Windows exe. Signing still only runs when SIGNPATH_ORGANIZATION_ID is set.
Worth a look
- Secret-bearing third-party signing action pinned to mutable tag, not commit SHA —
.github/workflows/release.yml:69· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 7 functions depend on the 7 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 7 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 7 function(s) in the blast radius were not formally verified this run
Bumps the actions group with 2 updates in the / directory: googleapis/release-please-action and signpath/github-action-submit-signing-request.
Updates
googleapis/release-please-actionfrom 4 to 5Release notes
Sourced from googleapis/release-please-action's releases.
... (truncated)
Changelog
Sourced from googleapis/release-please-action's changelog.
... (truncated)
Commits
45996edchore(main): release 5.0.0 (#1200)a8121b9chore: build dist (#1201)f533c26fix: bump release-please from 17.3.0 to 17.6.0 (#1199)46dfc01feat!: upgrade to node24 (#1188)Updates
signpath/github-action-submit-signing-requestfrom 2 to 3Commits
f6d0478Build from - 7336bb524a08c99aa48ba5065b00095eb2b0e09e. Original commit messag...ef0ce19Build from - 8ff04a5c1f8d21d18e1eb1fc41b698b425a83654. Original commit messag...a790881Build from - 9c89d7e4aa8c240d6deba49c8e4f52910fd41288. Original commit messag...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions